Create the database
A private PostgreSQL instance on RDS, reachable only from the API.
About 25 min · Verified 8 October 2026
The API stores links, click events and collections in PostgreSQL. You will use Amazon RDS, a managed database: AWS handles patching, backups and the operating system. The instance goes in the private subnets with public access turned off.
Create the subnet group#
RDS needs to know which subnets it may use. A DB subnet group is that list, and it must cover at least two Availability Zones.
Create shortlink-db-subnets#
Open RDSSubnet groupsCreate DB subnet group.
| Field | Value |
|---|---|
| Name | shortlink-db-subnets |
| Description | Private subnets for ShortLink |
| VPC | shortlink-vpc |
| Availability Zones | ap-south-1a and ap-south-1b |
| Subnets | 10.0.11.0/24 and 10.0.12.0/24 (the private ones) |
Choose Create.
Create the database#
Start the wizard#
Open RDSDatabasesCreate database. Choose Standard create and engine PostgreSQL.
Leave the engine version on the default. The reference deployment ran PostgreSQL 18; any current major version (15 or newer) works with this app.
Template, availability and identifier#
| Field | Value |
|---|---|
| Templates | Free tier if shown, otherwise Dev/Test (never Production) |
| Availability and durability | Single-AZ DB instance (or "Single DB instance") |
| DB instance identifier | shortlink-db |
Credentials#
| Field | Value |
|---|---|
| Master username | postgres |
| Credentials management | Self managed |
| Master password | A strong password you choose |
Instance and storage#
| Field | Value |
|---|---|
| DB instance class | Burstable classes → db.t3.micro |
| Storage type | General Purpose SSD (gp3) |
| Allocated storage | 20 GiB |
| Storage autoscaling | untick Enable storage autoscaling (avoids surprise growth) |
Connectivity#
| Field | Value |
|---|---|
| Compute resource | Don't connect to an EC2 compute resource |
| Network type | IPv4 |
| Virtual private cloud (VPC) | shortlink-vpc |
| DB subnet group | shortlink-db-subnets |
| Public access | No |
| VPC security group (firewall) | Choose existing → remove default, add shortlink-db-sg |
| Availability Zone | No preference |
| Database port | 5432 |
Additional configuration#
Expand Additional configuration at the bottom of the form.
| Field | Value |
|---|---|
| Initial database name | shortlink |
| Backup retention period | 1 day (7 is the default; 1 is fine for a workshop) |
| Encryption | leave Enable encryption ticked |
| Deletion protection | off for the workshop, so you can clean up |
Choose Create database. If the console offers to add optional features such as Performance Insights, you can decline.
Wait for Available and save the endpoint#
Creation takes 5 to 10 minutes. Open RDSDatabasesshortlink-db. When Status is Available, find Connectivity & security → Endpoint. It looks like shortlink-db.abcd1234.<region>.rds.amazonaws.com.
Copy it into My values → RDS endpoint.
Verify from the command line#
aws rds describe-db-instances --region ap-south-1 --db-instance-identifier shortlink-db \
--query 'DBInstances[0].{status:DBInstanceStatus,endpoint:Endpoint.Address,public:PubliclyAccessible,db:DBName,class:DBInstanceClass,storageGiB:AllocatedStorage}' \
--output tableThe db field must say shortlink and public must be False.
Two facts worth knowing#
- TLS is required. Recent PostgreSQL versions on RDS reject unencrypted connections. That is why the API's environment file sets
DB_SSL=true, which makes thepglibrary connect over TLS. - Always trust the console for the hostname. A stale hostname copied from an old note is the most common reason the API cannot reach the database. If you ever recreate the database, the endpoint changes, so update the API environment file. The troubleshooting chapter shows how to compare the two.
Next: IAM role for the server.
Found a mistake? Edit this page on GitHub.